3 ms·
I don't get what non-malicious reason there would be for not automatically verifying domain ownership of display urls as an advertising network. The advertiser
by bcye 2y ago
I don't get what non-malicious reason there would be for not automatically verifying domain ownership of display urls as an advertising network. The advertiser is highly likely to already have a Search Console account in which they'd have had to verify it, and URL verification is easily done by all kinds of systems via meta tags, CNAME or TXT entries, etc. Why not for ads?
- iambateman 2y agoWell… marketing and web development are often at war with one another inside individual organizations. And the person running the ads almost never has domain-verification authority. So Google doesn’t want to introduce a major barrier to accept money. I think that makes sense without being malicious.
- bcye 2y agoThe attack vector for scams seems immediately apparent, so this just seems very negligent. It also reduces the risk for advertisers as the profit from taking over an ad account is less if you can't direct users to malware from an account with good standing (of course there are still other ways to show malicious ads).
- compootr 2y agoI mean, Google is incentivized here to reduce friction on advertisers instead of protecting losses they wouldn't even incur from a malicious ad in other words, a malicious ad doesn't do much for them but actively increasing security is bad. yay capitalism